Skip to content

[ci] Add mechanism for trust on certain CI scripts#12604

Merged
driazati merged 1 commit intoapache:mainfrom
driazati:jtrust
Aug 30, 2022
Merged

[ci] Add mechanism for trust on certain CI scripts#12604
driazati merged 1 commit intoapache:mainfrom
driazati:jtrust

Conversation

@driazati
Copy link
Copy Markdown
Member

@driazati driazati commented Aug 25, 2022

This makes it so changes to certain files from users not listed in
CONTRIBUTING.md are not tested in CI. This is necessary since these
scripts run on the baremetal EC2 instances and not inside Docker
containers, so they can affect other builds and potentially grab Jenkins
secrets. This checks out the version from the upstream for the listed
files after running git checkout. Tested in CI: positive and negative

cc @Mousius @areusch @gigiblender

@driazati driazati marked this pull request as ready for review August 25, 2022 19:22
@github-actions
Copy link
Copy Markdown
Contributor

Built docs for commit cf114ce can be found here.

Copy link
Copy Markdown
Contributor

@areusch areusch left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mainly one question, which i think related to the test script refactor

Comment thread ci/jenkins/Jenkinsfile.j2 Outdated
@driazati driazati marked this pull request as draft August 25, 2022 22:53
@github-actions github-actions Bot requested a review from Mousius August 30, 2022 18:56
@driazati driazati marked this pull request as ready for review August 30, 2022 18:57
This makes it so changes to certain files from users not listed in
`CONTRIBUTING.md` are not tested in CI. This is necessary since these
scripts run on the baremetal EC2 instances and not inside Docker
containers, so they can affect other builds and potentially grab Jenkins
secrets. This checks out the version from the upstream for the listed
files after running `git checkout`.
@driazati driazati merged commit caf326f into apache:main Aug 30, 2022
areusch pushed a commit that referenced this pull request Sep 15, 2022
This should mitigate failures like in
https://ci.tlcpack.ai/blue/organizations/jenkins/tvm/detail/main/4274/pipeline.
This also moves the `retry` function to a script now that we have
PR #12604.

Co-authored-by: driazati <driazati@users.noreply.github.com>
xinetzone pushed a commit to daobook/tvm that referenced this pull request Nov 25, 2022
This makes it so changes to certain files from users not listed in
`CONTRIBUTING.md` are not tested in CI. This is necessary since these
scripts run on the baremetal EC2 instances and not inside Docker
containers, so they can affect other builds and potentially grab Jenkins
secrets. This checks out the version from the upstream for the listed
files after running `git checkout`. Tested in CI: [positive](https://ci.tlcpack.ai/blue/organizations/jenkins/tvm/detail/PR-12604/6/pipeline/) and [negative](https://ci.tlcpack.ai/blue/organizations/jenkins/tvm/detail/PR-12604/9/pipeline/)
xinetzone pushed a commit to daobook/tvm that referenced this pull request Nov 25, 2022
This should mitigate failures like in
https://ci.tlcpack.ai/blue/organizations/jenkins/tvm/detail/main/4274/pipeline.
This also moves the `retry` function to a script now that we have
PR apache#12604.

Co-authored-by: driazati <driazati@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants